Privacy

Privacy Policy

Last updated: April 2026

Flexync ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect information when you use our fitness business management platform ("the Service").

This policy is designed to comply with the General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act (DPDPA), and other applicable data protection laws.

1. Information We Collect

1.1 Personal Information

When you create an account or use the Service, we may collect:

  • Name, email address, and phone number
  • Business name and address
  • Billing and payment information (processed securely by our payment partners)
  • Profile photo (if uploaded)

1.2 Business Data

As a fitness business management platform, we store data you enter about your operations, including:

  • Member records (names, contact details, membership plans)
  • Staff information and roles
  • Attendance and scheduling records
  • Billing transactions and payment history
  • Workout and diet plans generated through the Service

1.3 Usage Data

We automatically collect certain information when you use the Service, including:

  • IP address and approximate location
  • Browser type, device type, and operating system
  • Pages visited, features used, and time spent on the Service
  • Referring URLs and search terms
  • Error logs and performance data

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process transactions and send billing-related communications
  • Send account notifications, security alerts, and support messages
  • Generate AI-powered workout and diet plans when requested
  • Analyse usage patterns to improve performance and user experience
  • Detect and prevent fraud, abuse, and security threats
  • Comply with legal obligations

We do not sell your personal information to third parties. We do not use your business data for advertising purposes.

3. Data Storage and Security

We take the security of your data seriously and implement industry-standard measures, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Tenant-level data isolation to ensure your business data is completely separate from other accounts
  • Regular security audits and vulnerability assessments
  • Access controls and role-based permissions
  • Secure password hashing using modern algorithms
  • Automated backups and disaster recovery procedures

While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security but will notify you promptly in the event of a data breach affecting your information.

4. Third-Party Services

We work with trusted third-party services to operate the platform. These include:

4.1 Payment Processors

We use third-party payment processors (such as Razorpay) to handle payment transactions. Your payment information is transmitted directly to these processors and is not stored on our servers. These processors comply with PCI-DSS standards.

4.2 AI Services — Anthropic Claude

Our AI-powered workout and diet plan features are powered by Anthropic's Claude AI. When you use these features, relevant member fitness data (such as fitness goals, health conditions, and preferences) is sent to Anthropic's API for processing. Anthropic does not use this data to train their models. Please refer to Anthropic's privacy policy for more details.

4.3 Hosting and Infrastructure

The Service is hosted on secure cloud infrastructure. Our hosting providers maintain physical and network security controls in compliance with industry standards.

We only share the minimum data necessary with third-party services and ensure each provider maintains appropriate data protection standards.

5. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential cookies: Required for the Service to function (authentication, session management, CSRF protection)
  • Preference cookies: Remember your settings such as theme preference (light/dark mode)
  • Analytics cookies: Help us understand how the Service is used so we can improve it

You can control cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the Service.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

  • Account data: Retained while your account is active, plus up to 90 days after termination
  • Business data: Retained while your account is active, plus up to 90 days after termination to allow data export
  • Usage and analytics data: Retained in anonymised form for up to 24 months
  • Billing records: Retained for up to 7 years as required by tax and financial regulations

After the retention period, data is permanently and irreversibly deleted from our systems, including backups.

7. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to correction: Request correction of inaccurate or incomplete data
  • Right to deletion: Request deletion of your personal data, subject to legal retention requirements
  • Right to data portability: Request your data in a structured, machine-readable format
  • Right to restrict processing: Request that we limit how we process your data
  • Right to object: Object to processing of your data for specific purposes
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us at hello@flexync.com. We will respond to your request within 30 days.

8. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you are a gym owner who manages members under 18, you are responsible for obtaining appropriate parental or guardian consent before entering their data into the system.

If we become aware that we have collected personal data from a child without proper consent, we will take steps to delete that information promptly.

9. International Data Transfers

Your data may be processed and stored in countries other than your own, including India and other regions where our infrastructure providers operate. When transferring data internationally, we ensure appropriate safeguards are in place, including:

  • Standard contractual clauses approved by relevant data protection authorities
  • Ensuring receiving parties maintain adequate data protection standards
  • Compliance with applicable cross-border data transfer regulations

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify you by email or through a prominent notice within the Service
  • Provide at least 15 days' notice before material changes take effect

We encourage you to review this policy periodically. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Flexync — Privacy Enquiries

Email: hello@flexync.com

Website: flexync.com

Location: India

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.